Who protects the tools protecting your clients?

You’ve spent years doing the responsible thing. Locking up passwords, account details, and firewall logins for all of your customers. You know how important this data is. That’s why you built a digital vault, secured it in a digital bank, and separated it for every customer. We know the bad guys have many ways to get in, but this data is treated like gold. They would need some Syfy hacking systems and three hundred years to crack this vault.

WRITTEN BY

Matt Vaillancourt, Director, Security Sales
NETGEAR Enterprise

  • Last Updated: August 31st, 2026

Then you showed up to work today and were greeted by someone out front holding a cardboard sign that says, “Master bank keys: $20”. The crown jewels, for basically nothing. Now what?

According to Dark Reading, a vulnerability in N-able software does roughly that, exposing the master keys for the password vaults MSPs use to manage credentials across entire client portfolios. As of that report, the CVE assignment and patch availability were unconfirmed, and the story is still single source. But when the thing potentially on fire is the master key to everything, do not wait politely for a second outlet to confirm the smoke before you start an internal incident response conversation.

I encourage all companies to have business continuity plans for all kinds of incidents. MSPs should have one too. Prisons do not wait for an inmate to escape to put together a plan for it. You should have a plan for this, too.

LastPass data breach in 2022 is the case everyone remembers: once the key material is out, encryption at rest is a formality and every vault in the system is in play. Once an attacker can reach vault data or master key material, the damage never stops at one client. It reaches every client whose credentials live in the system, and the blast radius scales with how well you did your job. The more diligently you consolidate, the more there is to lose. Competence becomes a risk multiplier.

What can I do to mitigate risk?

If you run N-central, the short list is mercifully short. CVE-2026-18577 is an actively exploited authentication bypass and admin takeover affecting both cloud and on-prem N-central through 2026.3.1. Attackers who get in gain admin access and can abuse the built-in Take Control feature to pivot straight into managed endpoints. You need 2026.3.1.7 or later. Anything before the emergency hotfix is considered vulnerable; run it now before your coffee gets cold.

Patching closes the door, but it does nothing about whoever may have already walked through it, so don’t stop there. N-able published six attacker IP addresses, so hunt your logs for those, look specifically for Take Control abuse and any Cloudflare tunnels left behind for persistence, and rotate credentials for anything a compromised instance could reach. Confirm all of it against N-able’s own security advisory channel rather than a blog, this one included, because parts of this are still developing and the trust center is where the authoritative version lives. Do this before you file it under a tidy ticket number and call it handled.

We are all taught to build our security practice in layers. This is where the architecture underneath the vault starts to matter more than the vault. If a stolen master credential is a skeleton key, a well-built ZTNA posture is the building that keeps asking who you are at every single door anyway. Zero trust does not care that you walked in holding a valid key. It re-checks identity, device posture, and context per request, so a credential lifted from a compromised vault doesn’t quietly become free rein across the environment. It becomes one more login that has to survive continuous scrutiny it was never designed to pass.

The identity layer took the week off

The N-able story does not stand alone this week, which is the theme (if a week of attacks on the thing we told everyone to trust can be called a theme).

Mirage2FA has surged against roughly 4,500 US and EU companies, per The Hacker News, abusing Microsoft 365 login flows to grab session tokens before MFA even finishes. Separately, there’s NovaCookies, a phishing-as-a-service kit running $320 a month according to Dark Reading, with the campaign mechanics corroborated by The Hacker News. It hijacks real DocuSign notification emails to steal authenticated session cookies after MFA has already done its part. Different doors, same burglary. MFA bypassed, session hijacked, account owned.

At prices like this, that’s not a nation-state line item. It’s a ransomware affiliate with a side hustle subscription service. Your SMB clients are exactly who this is built to reach.

The gap this all walks through is the distance between authenticating successfully and staying verified. Most Conditional Access policies check who you are at the moment you log in, then more or less take your word for it afterward. They rarely ask whether the session token used half an hour later still belongs to the same device, location, and risk profile. Adversary-in-the-middle and cookie theft attacks were designed, lovingly, to live in that exact blind spot.

For MSPs running M365 tenants, this week’s audit comes down to three questions:

  • Is Continuous Access Evaluation actually turned on across client tenants?
  • Are sign-in risk policies genuinely flagging impossible travel and unfamiliar devices, or just present in spirit?
  • Is Entra ID Protection configured rather than merely licensed and forgotten (which is the security equivalent of buying gym equipment and hanging laundry on it)?

This is the other place SASE quietly does the work that a login prompt cannot. Continuous, inline session evaluation is the whole point of the model. A SASE fabric watching traffic and posture in real time can flag or cut a session whose device, geography, and behavior stopped matching the human it was issued to, which is precisely the moment a stolen cookie tries to go for a walk. The token still gets stolen. It just stops being useful the instant it starts behaving like a thief.

Phishing-resistant authentication, meaning FIDO2 hardware keys or passkeys, closes this whole category structurally. SMS codes and authenticator apps don’t. If you’ve been waiting for a natural moment to move a client toward FIDO2, this week handed you the talking point gift-wrapped.

A perfect “10”

Underneath it all is a CVSS 10.0 unauthenticated remote code execution flaw in Microsoft Entra ID, patched by Microsoft and reported by The Hacker News. A maximum-severity, no-credentials-required RCE in an identity platform isn’t a hypothetical you can schedule around. If the vulnerable component was reachable before the patch, an attacker needed exactly nothing from you to run code in the identity plane.

This one is also single source, which is unusual for a 10.0 and deserves a little caution in how you repeat it outside your own walls. Internally, the action is dull and non-negotiable. Confirm the patch is applied across every client tenant. At this level, it’s worth checking everyone instead of spot-checking and assuming everything is okay. Microsoft Cloud services often patch silently, so verify through the Entra ID security advisories portal. Any client with incident notification windows in their compliance posture gets a short brief now, which is a far better conversation than the one that starts with them asking why they heard about it later.

The question we need to answer

What is your breach response plan when the compromised system is your own tooling?

Client breach response is rehearsed ground for most MSPs. Your own RMM going dark, your own vault getting hit, your own tenant being the front door- those are the scenarios that might be mentioned in an IR plan but are more often shrugged at. The N-able story, whether it hardens into something severe or quietly resolves lower, is a perfectly good excuse to write that plan while it’s still an exercise and not weekend overtime that you’ll remember for the wrong reasons.

Attackers worked out a while ago that the MSP is the most efficient path to dozens of clients at once. It’s why the identity layer and the management tooling keep taking the hits. A layered posture that assumes breach and keeps verifying anyway. SASE and ZTNA do the continuous checking that a one-time login never could, so you can make sure a compromise somewhere doesn’t become a compromise everywhere. Most MSP incident response plans still assume the attacker starts at the client. Unfortunately, attackers no longer agree with that assumption.

 

 

Sources

  1. N-able Bug Exposes Password Vault Master Keys — Dark Reading, 2026-08-20
  2. Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows — The Hacker News, 2026-08-25
  3. ‘NovaCookies’ Kit Steals Microsoft 365 Sessions for $320 a Month — Dark Reading, 2026-08-26
  4. NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions — The Hacker News, 2026-08-26
  5. Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution — The Hacker News, 2026-08-21
  6. The MFA Identity Trap: When Authentication Creates a False Sense of Security — SecurityWeek, 2026-08-26
  7. From Fake Workers to Account Recovery: The Growing Identity Verification Risk — BleepingComputer, 2026-08-25